osquery

osquery · osquery.osquery

SQL powered operating system instrumentation, monitoring, and analytics.

winget install --id osquery.osquery --exact --source winget

Latest 5.22.1

Release Notes

5.22.0 macOS binaries will not execute because the signing certificate is out of sync with the provisioning profile. 5.22.1 replaces it. What's Changed Features

  • Make escapeNonPrintableBytes UTF-8 aware by @nulmete in #8777
    • Note: This changes some query results that formerly were rendered as raw unicode bytes and will now be rendered as the corresponding characters.
  • Update virtual sql functions to support multiple constraints by @brian-mckinney in #8746
    • This allows SELECT * FROM vscode_extensions WHERE uid in (SELECT uid FROM users WHERE include_remote = 1) and similar queries that join or subquery to the users table to include results for remote users.
  • Add support for retries in carver by @zwass in #8740
  • Preserve file metadata in carver archives by @zwass in #8752
  • Add machine-wide provisioned MSIX packages to programs table (#8001) by @getvictor in #8772 Build & Dependencies
  • Update osquery-toolchain to 1.2.0 (LLVM 11.0.0, zlib 1.2.13) by @zwass in #8773
  • Update Apple provisioning profile for new developer certificates by @zwass in #8780
  • build: suppress enum-constexpr-conversion error for boost mpl on macos by @sharvilshah in #8742
  • lib: Update openssl to 3.6.1 by @sharvilshah in #8766 Fixes
  • Quit carving when sending a block fails by @zwass in #8733
  • Fix SMBIOS CPU count by @agiacomolli in #8737
  • Fix systemd unit: use .target instead of .service by @ideologysec in #8771
  • Fix typo in winbaseobj.table description by @SquidCooki2 in #8768
  • Fix JSON handling copy vs. ref semantics by @zwass in #8738
  • Fix memory leak in logon_sessions by @directionless in #8779 New Contributors
  • @ideologysec made their first contribution in #8771
  • @SquidCooki2 made their first contribution in #8768
  • @nulmete made their first contribution in #8777
  • @brian-mckinney made their first contribution in #8746 Full Changelog: 5.21.0...5.22.1

Installer type: wix

Architecture Scope Download SHA256
x64 Download 91238C6F7543979E59D88886D61E8E7A222F6595F89B24BFAC385D31433F7A02

Details

Homepage
https://osquery.io/
License
Apache-2.0 OR GPL-2.0-only
Publisher
osquery
Support
https://github.com/osquery/osquery/issues

Tags

hacktoberfestintrusion-detectionmonitoringsecuritysql

Older versions (9)

5.21.0
Architecture Scope Download SHA256
x64 Download 573E53F9C5E8BE3B356CAB1CD1A4C4BB175E811B89BE7AD89D04AFAC8527B464
5.20.0
Architecture Scope Download SHA256
x64 Download 68BC735B82AEB7AF8660A770B6626BE2ADBA5403E8112C62BAB254BA5B917960
5.19.0
Architecture Scope Download SHA256
x64 Download 6FE06CAB43A31C596E4001616EEE66FB32556BF5C228C4A4BA6DAF2897EDC1A3
5.18.1
Architecture Scope Download SHA256
x64 Download BA4C5DEF84E35EF101FC4EC3F47DD2124C66D736F0F124ACDB18C7B29DF253FE
5.17.0
Architecture Scope Download SHA256
x64 Download AF3CD2F989F7F7ACA667291674EDA4656F7795A7559F47E72521E71B31FF3BA5
5.16.0
Architecture Scope Download SHA256
x64 Download BE40425E0E4C182F9A1B882FC12A8B81FA4E872D3CD27AAD62AEE0CD1FAC7038
5.11.0
Architecture Scope Download SHA256
x64 Download 825BF75D0DCA88A5E8CEA699B90696738BD9BE44C9B8CFCE3906A3E2AB49B156
5.8.2
Architecture Scope Download SHA256
x64 Download D319837D4E95D1E477C2126D383501180925A29F488FF1164FA16D2E576F96DD
5.6.0
Architecture Scope Download SHA256
x64 Download C480B7B0352FB19B952DF9C0331926F134B1234DA716C8B12B6A9C5E19CABCE9